<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MacOS PEAP-MSCHAPv2 computer authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/macos-peap-mschapv2-computer-authentication/m-p/4404510#M567345</link>
    <description>&lt;P&gt;Never mind, I managed to figure out. I can see the password is saved in Active Directory. It seems MacOS behaves the same way as Windows.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 May 2021 08:55:55 GMT</pubDate>
    <dc:creator>vsurresh</dc:creator>
    <dc:date>2021-05-18T08:55:55Z</dc:date>
    <item>
      <title>MacOS PEAP-MSCHAPv2 computer authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/macos-peap-mschapv2-computer-authentication/m-p/4404077#M567335</link>
      <description>&lt;P&gt;Hello.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I know there's been plenty of topics regarding Windows based 802.1X computer authentication but none of them seem to provide an explanation for MacOS.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I'm familiar with how 'user authentication' works on MacOS but struggling to understand the 'computer authentication' The requirement is to ONLY use 'computer authentication' with 802.1X so, if a user has a company issued/domain joined MacBook the access should be granted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;With PEAP-MSCHAPv2 which computer credentials are exchanged between the client and ISE? The username would be the computer name (which exists in AD) but what about the password? My understanding is that PEAP requires username AND a password.&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment the authentication works as expected but I'm struggling to understand the password MacBook sends out to ISE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example: If the name of the computer is domain\EX1234 then ISE log shows this as the 'username'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Windows-10 - I understand that when a Windows based computer joins AD, a password is automatically created and being used with PEAP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 13:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macos-peap-mschapv2-computer-authentication/m-p/4404077#M567335</guid>
      <dc:creator>vsurresh</dc:creator>
      <dc:date>2021-05-17T13:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: MacOS PEAP-MSCHAPv2 computer authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/macos-peap-mschapv2-computer-authentication/m-p/4404510#M567345</link>
      <description>&lt;P&gt;Never mind, I managed to figure out. I can see the password is saved in Active Directory. It seems MacOS behaves the same way as Windows.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 08:55:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/macos-peap-mschapv2-computer-authentication/m-p/4404510#M567345</guid>
      <dc:creator>vsurresh</dc:creator>
      <dc:date>2021-05-18T08:55:55Z</dc:date>
    </item>
  </channel>
</rss>

